- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 33,136
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Cedars-Sinai Health System, reported that an employee’s unencrypted laptop computer was stolen during a residential burglary. Although the computer was used primarily for troubleshooting pathology software, some electronic protected health information (ePHI) of approximately 33,136 individuals was potentially stored in temporary files on the laptop’s hard drive. The CE terminated the laptop’s remote access capabilities and conducted an internal investigation. Although the CE’s laptops are encrypted as per its policy, the encryption for this laptop was disabled by a helpdesk service provider when providing assistance. The CE provided breach notification to HHS, affected individuals, and the media, and posted notice of the incident on its website. The CE has not learned of any identity theft or other misuse of the potentially affected information resulting from this incident. Following OCR’s investigation, the CE updated its policies and procedures related to the storage, transmission and encryption of ePHI, as well as the enforcement of its employees’ adherence to these policies and procedures.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.